GHSA-rw87-6jm9-frwwMediumCVSS 6.1

The LifterLMS WordPress plugin before 10.0.10 does not strip event-handler attributes from a...

Published
July 30, 2026
Last Modified
July 30, 2026

🔗 CVE IDs covered (1)

📋 Description

The LifterLMS WordPress plugin before 10.0.10 does not strip event-handler attributes from a course pricing field before storing and rendering it, allowing users with a course-editing role to inject JavaScript that executes in the session of an administrator who views the course.

🔗 References (3)